Mediabistro logo
job logo

Government and Public Sector - Cybersecurity Operations & Threat Detection Respo

Ernst & Young Advisory Services Sdn Bhd, Mc Lean, VA, United States


Government and Public Sector - Cybersecurity Operations & Threat Detection Response - Senior Manager
Location: McLean

Other locations: Primary Location Only

Date: Mar 27, 2026

Requisition ID: 1697104

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Government and Public Sector - Technology Consulting - Cybersecurity Operations & Threat Detection - Senior Manager

From strategy to execution, the Government & Public Sector practice (“GPS”) of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes.

The opportunity

As a Senior Manager in Security Operations & Threat Detection and Response within EY’s Government & Public Sector (GPS) practice, you will lead the strategy, design, transformation, and operation of mission‑critical Security Operations Centers (SOCs) for federal, state, local, and education clients.

This role blends strategic cybersecurity advisory, operational leadership, and business development ownership in classified and highly regulated environments, up to the Top Secret (TS) level.

Your key responsibilities

Define and drive security operations strategies and target operating models aligned to agency missions, risk tolerance, and regulatory mandates.

Design and implement SOC operating models that support cleared, U.S.-based delivery in environments up to the TS level, hybrid architectures, and follow‑the‑sun coverage where permissible.

Own engagement delivery outcomes, ensuring services meet EY quality standards, contractual SLAs, and government client expectations.

Contribute to the development of EY GPS and global cybersecurity methodologies, assets, and accelerators in Threat Detection & Response.

Lead the design and operation of AI‑enabled and automation‑driven SOC capabilities, including agent‑based workflows and advanced analytics that accelerate alert triage, enrichment, and response.

Drive XDR‑led detection strategies, unifying telemetry across EDR, NDR, SIEM, identity, cloud, and SaaS platforms into a coherent and prioritized threat detection model.

Oversee multi‑cloud and hybrid SOC architectures, integrating Azure, AWS, and on‑prem environments into centralized detection and response operations.

Own security operations performance metrics, including MTTD, MTTR, dwell time, alert fidelity, and automation coverage, using these KPIs to drive continuous improvement and executive‑level reporting.

Establish fusion across adjacent operational domains, including vulnerability management, identity security, data protection, and threat intelligence, reflecting how GPS programs are funded, governed, and measured.

Oversee day‑to‑day SOC operations supporting

classified (up to TS) and unclassified environments , including:

Threat monitoring, alert triage, and escalation

Incident containment, eradication, and recovery coordination

Detection engineering, use‑case development, advanced analytics, and tuning across SIEM and XDR platforms

Threat hunting and integration of cyber threat intelligence

SIEM and SOAR runbook development and optimization

Act as Incident Commander and executive escalation point for high‑severity cyber incidents, coordinating response with client leadership and government stakeholders.

Integration of automated response and orchestration to reduce analyst burden and improve response consistency.

Lead post‑incident reviews using MITRE ATT&CK and adversary‑informed defense techniques to measurably improve detection coverage and response effectiveness.

Advise senior government stakeholders on SOC modernization roadmaps, translating operational metrics and detection outcomes into mission risk, compliance posture, and investment justification.

Lead SOC assessments and maturity reviews using EY and industry frameworks (e.g., NIST CSF, NIST 800‑53, RMF, ISO 27001).

Develop actionable roadmaps to mature clients’ SecOps capabilities across tooling, cleared workforce models, processes, and governance.

Prepare and deliver client‑ready proposals, Statements of Work (SoWs), executive briefings, and classified or unclassified presentations as required.

Ensure adherence to EY risk management, independence, and quality standards across all engagements.

Oversee documentation of SOC procedures, incident records, and governance artifacts to support audits, inspections, and regulatory reviews.

Support clients in aligning security operations with public sector mandates and regulations (e.g., FISMA, FedRAMP, CMMC, NIST, Zero Trust).

Lead business development efforts for Security Operations, SOC transformation, and managed detection and response engagements across GPS clients.

Originate opportunities by building trusted relationships with senior government stakeholders and identifying mission‑driven and regulatory cybersecurity needs.

Own and lead end‑to‑end pursuits, including:

Opportunity shaping and qualification

Solution architecture and cleared delivery model design

Pricing, margin management, and risk review

RFP/RFI responses, orals, and executive negotiations

Serve as the primary relationship lead for assigned accounts, driving account planning, pipeline development, and sustained revenue growth.

Lead, mentor, and develop multidisciplinary teams of analysts, engineers, and consultants.

Foster an inclusive, collaborative culture aligned with EY values and public service mission outcomes.

To qualify for the role you must have

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field; Master’s degree preferred.

Typically 8–12+ years of cybersecurity experience, including 4–5+ years in SOC or incident response leadership roles.

Experience leading large, complex cybersecurity engagements in consulting or managed services environments.

Demonstrated experience supporting government or highly regulated clients.

Must be comfortable working in‑person as needed.

Professional Certifications (highly desirable):

2 or more of: GIAC Security Expert (GSE) preferred or other SANS GIAC certifications; CISSP, CISM, CISA, CRISC; ITIL Foundation or higher.

Cloud and modern security certifications are an advantage: CCSP, Microsoft SC 200/SC 100, Azure Security Engineer, AWS Security Specialty, Google Professional Cloud Security Engineer.

Ideally, you’ll also have

Proven ability to lead client engagements end‑to‑end while owning pipeline and revenue growth.

Strong commercial acumen, including pricing, margin management, and risk governance.

Executive‑level communication, stakeholder management, and negotiation skills.

Ability to operate calmly and decisively during high‑pressure cyber incidents. Deep understanding of SOC operations (Tier 1–3), incident response lifecycle, and threat hunting.

Demonstrated ability to make senior‑level technical decisions across detection engineering, incident response, and adversary tradecraft in complex government environments.

An active U.S. security clearance is required due to the nature of government client work.

Top Secret (TS) clearance is highly preferred.

What we offer you
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $170,600 to $390,000. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $204,800 to $443,200. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

Jointly with the compensation, our hybrid model expects most people in external, client serving roles to work together in person 40‑60% of the time over the course of an engagement, project or year.

Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well‑being.

Equal Employment Opportunity Statement
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity or expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

Reasonable Accommodation for Persons with Disabilities
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.

#J-18808-Ljbffr